"Version": "2012-10-17", "Statement": [ { "Sid": "VisualEditor0", "Effect": "Allow", "Action": [ "logs:CreateLogStream", "cloudwatch:", "s3:", "ec2:AssociateRouteTable", "ec2:CreateRoute", "ec2:CreateRouteTable", "ec2:DeleteRoute", "ec2:DeleteRouteTable", "ec2:DescribeRouteTables", "ec2:DescribeVpcs", "ec2:ReplaceRoute", "ec2:DescribeRegions", "ec2:DescribeNetworkInterfaces", "ec2:DisassociateRouteTable", "ec2:ReplaceRouteTableAssociation", "logs:CreateLogGroup", "logs:PutLogEvents" ], "Resource": "*" } ] } Destination Target 192.168.0.0/16 eni-**01 (C8000V#1) ⇒ eni-**02 (C8000V#2) 172.31.0/16 local C8000V#2 (AWS版) guestshell csr_ha.service インスタンス 障害 【Route table: rt-private】 Tunnel Interface上で BFDと動的ルーティングを動作させて障害を検知 障害検知時に Route tableのTargetを書き換え 必要な権限 (IAM Policy)